网络安全 · AI 攻防全景图 · 2026-07 版Cybersecurity · The AI Attack-Defense Landscape · Jul 2026

新枪发给了双方,
地基还是老三样
Both sides got new guns.
The floor is still the old three

AI 同时武装了攻方守方——攻方拿到的是规模化的钓鱼、深伪与漏洞利用提速,守方拿到的是分诊、检测与响应的自动化。但把两把新枪放下之后,决定一家机构生死的那 80% 风险,答案仍然是三十年前那三样:抗钓鱼 MFA、按实际被利用清单打补丁、离线不可变备份并演练恢复。这不是保守,是算术:身份攻击里 99% 以上走的是密码,而抗钓鱼 MFA 把这一类风险降 >99%。AI 是放大器,不是地基替代品——把预算砸在没打补丁的资产上,等于给漏水的船装涡轮增压。本图因此按「基本功 ROI」而不是按「技术先进度」排序:先把地基做完,再谈智能体化 SOC。 AI armed the attacker and the defender in the same breath — phishing, deepfakes and exploit development at scale on one side; triage, detection and response automation on the other. Put both guns down, however, and the 80% of risk that actually decides an organisation’s survival still answers to the same three things it did thirty years ago: phishing-resistant MFA, patching by what is actually exploited, and offline immutable backups that have been restored in a drill. That is not conservatism but arithmetic: passwords carry over 99% of identity attacks, and phishing-resistant MFA cuts that risk by more than 99%. AI amplifies; it does not replace the floor — spend on AI while assets go unpatched and you have turbocharged a leaking boat. This map is therefore ordered by return on fundamentals rather than by sophistication: finish the floor, then talk about the agentic SOC.

「九成入侵始于一封钓鱼邮件——技术漏洞可以补,人性软肋补不了。」这是全行业最古老、也最没被 AI 改写的一条铁律。"Nine in ten breaches start with a phishing email — you can patch a vulnerability, you can't patch human nature." The industry's oldest law, and the one AI has rewritten least.
「AI 是放大器,不是地基替代品——把 AI 预算砸在没打补丁的资产上,等于给漏水的船装涡轮增压。」"AI is an amplifier, not a foundation replacement — spending the AI budget on unpatched assets is turbocharging a leaking boat."

五大版图外加一份产品指南:攻防双轨杀伤链(侦察→初始访问→立足→提权→横向移动→驻留→窃取勒索,每段红蓝对垒)、Security for AI 新纵列(AI 本身成为新攻击面)、基本功 ROI 三梯队全球 × 中国厂商竞技场(并购潮)、机会与雷区矩阵(按角色筛选)。深伪技术与 news 图擦边——那里讲舆论信息战,本图讲它作为金融诈骗与社工入口的攻击链。 Five maps plus a product guide: the dual-track kill chain (recon → initial access → foothold → privilege → lateral → persistence → exfiltration, red vs blue at every stage), the Security-for-AI column (AI itself as a new attack surface), the fundamentals ROI ladder, the global × China vendor arena (the M&A wave), and the opportunity-and-minefield matrix filterable by role. Deepfakes overlap with the news map — that one covers information warfare, this one covers deepfakes as the attack chain for financial fraud and social engineering.

攻方 AIOffensive AI
守方 AIDefensive AI
AI 自身安全Security for AI
基本功地基The fundamentals
传统节点Traditional
80%
基本功(抗钓鱼 MFA + 补丁 + 不可变备份)吃掉的风险——CIS 前五控制防 85%+ 已知技术、微软基础卫生防 99% 常见攻击;AI 是放大器,不是地基Risk absorbed by fundamentals (phishing-resistant MFA + patching + immutable backups) — CIS's top-5 controls stop 85%+ of known techniques, Microsoft's basic hygiene stops 99% of common attacks; AI amplifies, it isn't the foundation
12
漏洞披露→被利用的中位时间 TTE(2021 年还是 32 天)——AI 把补丁到 exploit 压缩到数小时内,而用户中招钓鱼的中位时间不到 60 秒Median time-to-exploit after disclosure (32 days back in 2021) — AI compresses patch-to-exploit to hours; the median time for a user to fall for phishing is under 60 seconds
$320亿
Google 收购 Wiz——史上最大网络安全收购;叠加 Palo Alto $250 亿收 CyberArk:平台整合潮几乎把 AI 安全初创收编殆尽Google's acquisition of Wiz — the largest cybersecurity deal ever; stacked on Palo Alto's $25B for CyberArk, the consolidation wave has absorbed nearly every AI-security startup
82
每个人对应的机器身份数(CyberArk 2025),42% 有特权访问——「AI 智能体是终极特权用户」,身份成为新边界Machine identities per human (CyberArk 2025), 42% with privileged access — "the AI agent is the ultimate privileged user"; identity is the new perimeter
口径警告:AI 钓鱼有效性各源分歧极大(点击率 54%[全景] ↔ 11% vs 人工 14%[compass],相差 5 倍,图中并列不取单值);厂商自述效率数字(奇安信 60 倍 / 深信服 96.6% / CrowdStrike 98% / 微软 550%)标 ⚑「厂商自述」角标,未经第三方验证;GTG-1002「AI 自主国家级攻击」为 Anthropic 单方披露且模型会夸大编造;「全自主攻击链」尚未成真(Google「未观察到突破性能力」);IDC 2028 市场预测为预测非事实。 Basis warning: AI phishing efficacy diverges wildly by source (click rate 54% [全景] ↔ 11% vs 14% human [compass], a 5x gap — shown side by side, no single value taken); vendor-claimed efficiency figures (QiAnXin 60x / Sangfor 96.6% / CrowdStrike 98% / Microsoft 550%) carry a ⚑ "vendor claim" flag, unverified by third parties; GTG-1002's "autonomous state-level AI attack" is Anthropic's sole disclosure with a model that exaggerates and fabricates; the "fully autonomous attack chain" hasn't materialized (Google: "no breakthrough capability observed"); IDC's 2028 forecast is a projection, not fact.
Reading the MapReading the Map

从这张图看到的五条规律Five patterns this map makes visible